Skip to content

Repository files navigation

Vault logo

Vault

Private by design. Offline by default.

Secure local vault for API keys, passwords, tokens, SSH keys, notes, JSON, .env files, and any other sensitive text.

CI Tauri Rust Offline License: MIT

Vault is a desktop-first, zero-cloud secret manager. Your data is encrypted locally before it is written to SQLite, and the master password is never stored. There is no account, telemetry, sync service, or network dependency.

Highlights

  • Store API keys, secret keys, access tokens, passwords, SSH private keys, recovery codes, license keys, environment variables, secure notes, plain text, JSON, and .env configuration.
  • Search, filter, tag, favorite, copy, reveal, edit, and delete entries from a focused desktop interface.
  • Export the entire vault to a password-protected .vault backup and import it on another device.
  • Auto-locks after five minutes of inactivity and clears copied secrets from the clipboard after 30 seconds.
  • Checks for signed updates in-app and lets you download, install, and restart from one click.
  • Cross-platform Tauri shell with a Rust security boundary and a React + TypeScript UI.

Security

Vault uses application-layer encryption so the SQLite database contains encrypted payloads rather than readable secrets:

Layer Implementation
Key derivation Argon2id, 64 MiB memory, 3 iterations, 16-byte random salt
Item encryption AES-256-GCM with a fresh 12-byte nonce per item
Key lifetime Master key is held only in memory while the vault is unlocked
Database Local SQLite with WAL and synchronous writes enabled
Export Separate AES-256-GCM backup key derived from an export password
Network CSP and application design keep the vault offline

Security note: Vault is designed for local use. Keep your master password and backup password safe; they cannot be recovered by the application.

Getting started

Prerequisites

  • Node.js 20 or newer
  • Rust stable and Cargo
  • Tauri prerequisites for your operating system (official guide)

Development

git clone https://github.com/codeverta/vault.codeverta.com.git
cd vault.codeverta.com
npm install
npm run tauri dev

On first launch, create a master password with at least 10 characters. The vault database is created in the operating system's application-data directory.

Installation

Download a release

Download the latest installer from the GitHub Releases page. Vault release builds are produced for:

Platform Artifact
macOS Apple Silicon .dmg and .app.tar.gz
Linux x64 .AppImage and .deb
Windows x64 .msi and .exe

Build a production app

npm run tauri build

Bundled installers are written to src-tauri/target/release/bundle/. The GitHub release workflow builds macOS, Linux, and Windows artifacts in parallel.

Frontend-only checks

npm run check     # TypeScript
npm run build     # Vite production bundle

Rust checks and tests

cargo check --manifest-path src-tauri/Cargo.toml
cargo test --manifest-path src-tauri/Cargo.toml
cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings

Publish without cloning again

From this existing workspace, npm run release:local builds the current platform and uploads the installers to GitHub Releases. To build macOS, Linux, and Windows in GitHub Actions without downloading the repository yourself, run npm run release:ci.

See the release guide for signing setup and the complete workflow.

Backup and migration

  1. Open Settings → Export & import.
  2. Choose a dedicated backup password and export a .vault file.
  3. Copy the file to the new device through your preferred secure channel.
  4. Create or unlock Vault on the new device, then import the backup with its backup password.

The backup password is separate from the master password. Vault never uploads or syncs this file.

In-app updates

When a newer signed release is available, Vault shows an Update button in the sidebar. Click it once to download, verify, install, and restart the application. No manual binary download is needed. Updates are verified against the public key bundled in the application.

Project structure

src/                 React + TypeScript interface
src-tauri/src/       Rust commands, encryption, and SQLite storage
src-tauri/icons/     Application icon assets
.github/workflows/   Continuous integration checks
docs/                Developer and release documentation

Contributing

Bug reports and pull requests are welcome. Start with the developer documentation and read CONTRIBUTING.md before opening a change. The release guide covers versioning and publishing. Never include real credentials, tokens, private keys, or .vault backups in an issue or pull request.

For security issues, please follow SECURITY.md rather than opening a public issue.

License

Vault is released under the MIT License.


Built with care for people who prefer their secrets to stay on their own devices.
◆ Codeverta · Vault · 2026 ◆
# vault.codeverta.com

About

Vault is a desktop-first, zero-cloud secret manager. Your data is encrypted locally before it is written to SQLite, and the master password is never stored. There is no account, telemetry, sync service, or network dependency.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages